rootpwn

critical · CVSS v3 9.1

CVE-2026-81810

The All-in-One WP Migration and Backup plugin for WordPress fails to enforce proper capability checks on multiple AJAX actions. This oversig

Overview

The All-in-One WP Migration and Backup plugin for WordPress fails to enforce proper capability checks on multiple AJAX actions. This oversight allows users with export privileges to import arbitrary site archives and escalate privileges to administrator under specific misconfigurations.

Description

The All-in-One WP Migration and Backup WordPress plugin before 7.111 does not perform any capability check on several of its AJAX actions, gating them only on an installation-wide secret which it discloses to any user permitted to export the site, allowing such a user to import an arbitrary site archive and gain administrator access. Exploitation requires an administrator to have granted the export capability to a role that does not hold the All-in-One WP Migration and Backup WordPress plugin before 7.111's own import capability, which is not a default configuration.

Impact

Lowers confidentiality, integrity, and availability of the WordPress site by enabling unauthorized administrative access. Primarily impacts organizations utilizing non-default role configurations where export permissions are granted separately from import permissions.

Remediation

Update the All-in-One WP Migration and Backup plugin to version 7.111 or later. Review and audit WordPress user roles and permissions to ensure export and import capabilities are tightly controlled and restricted to trusted administrators.

Risk context

Rated as critical with a CVSS v3 score of 9.1, though exploitation requires specific non-default role configurations and prior export privileges. Defenders should prioritize patching based on local privilege assignment reviews.

Affected products

  • ServMask All-in-One WP Migration and Backup plugin

Scores

Severity
critical
CVSS v2
6.4
CVSS v3
9.1
CVSS v4
EPSS

WordPress Plugin Privilege Escalation AJAX Access Control

← All CVEs